MAL-2026-13157
Dashboard / Malicious Package / MAL-2026-13157
MAL-2026-13157
Summary: Malicious code in dolyame-ui-grid (npm)
Details: Source: amazon-inspector (f21d1f60c7f97ffdc8e698c9804d9d9116f286be7a026a9c90f6e4a1858dea18) On require('dolyame-ui-grid'), index.js loads _polyfill.js which selects a platform-specific asset, downloads a binary from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) with DNS-TXT chunked fallbacks under *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes it to /tmp or the Windows Temp directory under a disguised name (.cache_<rand> or dotnet_diag_<rand>.exe), chmods it 0755, and spawns it detached via spawn('/bin/sh') or spawn('cmd'). Destination hostnames are assembled at runtime by.join('') on split string fragments, and a.analytics_state mtime file gates re-execution cadence, with comments framing the code as 'telemetry'/'analytics'. A parallel dropper implementation in lib/telemetry.js (base64-decoded chunks, chmodSync 0755, cp.spawn('/bin/sh',['-c', filePath+' &'])) is present but not reachable from the main require graph. The download hosts are unrelated to the package publisher, the fetched bytes are opaque and unverified, and execution happens unconditionally on module load.
Affected packages
Package
Name: dolyame-ui-grid
Purl: pkg:npm/dolyame-ui-grid
Affected ranges
Type: N/A
Events:
